Data processing

Clear roles.
Narrow purpose.

Who is responsible for what, and the commitments we hold ourselves to — written plainly, enforced by the system.

The roles

Three parties, three responsibilities.

B
Each business

Controller of its own customer data — its leads, conversations, bookings and payments live in its own portals, under its own brand, connected to its own accounts.

A
The agency

Controller of its own operational data, and the business's partner for growth — working with performance and operational signals, under access each owner grants and can revoke.

P
PlexWizz

The processor and infrastructure: we process data only to provide the platform, on documented instructions — never for our own purposes.

Our commitments

What we will and will not do.

Always
  • Process only to provide the platform, on documented instructions
  • Encrypt credentials at rest and all traffic in transit
  • Keep every tenant and every business isolated at the application and database layer
  • Adhere to the Google API Services User Data Policy, including Limited Use
  • On exit: one-click export and complete erasure, enforced by database integrity rules — backup copies age out on a 7-day rotation
  • Notify affected customers of a personal-data breach without undue delay
Never
  • Sell data, rent data, or use it for advertising of our own
  • Train AI models on customer data
  • Move data across tenant or business boundaries
  • Store mailbox contents — mail is read live; only short-lived, self-clearing delivery caches exist
  • Touch funds or card data — payments run on hosted checkout, straight to the owner's accounts
  • Hold anything hostage on exit
We work with a small set of vetted infrastructure and service providers, each bound by data-processing terms at least as protective as ours. The current provider list and our signable Data Processing Agreement are provided to customers at contracting — and any time on request at support@plexwizz.com.
Questions?

We answer plainly.